Skip to content

Create the database

A private PostgreSQL instance on RDS, reachable only from the API.

About 25 min · Verified 8 October 2026

0 of 9 steps done0%

The API stores links, click events and collections in PostgreSQL. You will use Amazon RDS, a managed database: AWS handles patching, backups and the operating system. The instance goes in the private subnets with public access turned off.

Create the subnet group#

RDS needs to know which subnets it may use. A DB subnet group is that list, and it must cover at least two Availability Zones.

Open RDSSubnet groupsCreate DB subnet group.

FieldValue
Nameshortlink-db-subnets
DescriptionPrivate subnets for ShortLink
VPCshortlink-vpc
Availability Zonesap-south-1a and ap-south-1b
Subnets10.0.11.0/24 and 10.0.12.0/24 (the private ones)

Choose Create.

Create the database#

Start the wizard#

Open RDSDatabasesCreate database. Choose Standard create and engine PostgreSQL.

Leave the engine version on the default. The reference deployment ran PostgreSQL 18; any current major version (15 or newer) works with this app.

Template, availability and identifier#

FieldValue
TemplatesFree tier if shown, otherwise Dev/Test (never Production)
Availability and durabilitySingle-AZ DB instance (or "Single DB instance")
DB instance identifiershortlink-db

Credentials#

FieldValue
Master usernamepostgres
Credentials managementSelf managed
Master passwordA strong password you choose

Instance and storage#

FieldValue
DB instance classBurstable classes → db.t3.micro
Storage typeGeneral Purpose SSD (gp3)
Allocated storage20 GiB
Storage autoscalinguntick Enable storage autoscaling (avoids surprise growth)

Connectivity#

FieldValue
Compute resourceDon't connect to an EC2 compute resource
Network typeIPv4
Virtual private cloud (VPC)shortlink-vpc
DB subnet groupshortlink-db-subnets
Public accessNo
VPC security group (firewall)Choose existing → remove default, add shortlink-db-sg
Availability ZoneNo preference
Database port5432

Additional configuration#

Expand Additional configuration at the bottom of the form.

FieldValue
Initial database nameshortlink
Backup retention period1 day (7 is the default; 1 is fine for a workshop)
Encryptionleave Enable encryption ticked
Deletion protectionoff for the workshop, so you can clean up

Choose Create database. If the console offers to add optional features such as Performance Insights, you can decline.

Wait for Available and save the endpoint#

Creation takes 5 to 10 minutes. Open RDSDatabasesshortlink-db. When Status is Available, find Connectivity & security → Endpoint. It looks like shortlink-db.abcd1234.<region>.rds.amazonaws.com.

Copy it into My values → RDS endpoint.

You should see
Status Available, Publicly accessible: No, and an endpoint hostname you have saved.

Verify from the command line#

Your computerCheck the database
aws rds describe-db-instances --region ap-south-1 --db-instance-identifier shortlink-db \
  --query 'DBInstances[0].{status:DBInstanceStatus,endpoint:Endpoint.Address,public:PubliclyAccessible,db:DBName,class:DBInstanceClass,storageGiB:AllocatedStorage}' \
  --output table

The db field must say shortlink and public must be False.

Two facts worth knowing#

  • TLS is required. Recent PostgreSQL versions on RDS reject unencrypted connections. That is why the API's environment file sets DB_SSL=true, which makes the pg library connect over TLS.
  • Always trust the console for the hostname. A stale hostname copied from an old note is the most common reason the API cannot reach the database. If you ever recreate the database, the endpoint changes, so update the API environment file. The troubleshooting chapter shows how to compare the two.

Next: IAM role for the server.

Found a mistake? Edit this page on GitHub.